CVE-2019-8062 describes an insecure library loading (DLL hijacking) vulnerability in Adobe After Effects versions 16 and earlier. This flaw, rated 7.8 HIGH on CVSS, could allow an unauthenticated attacker to achieve arbitrary code execution if a user is tricked into opening a malicious file. While no public exploits or active exploitation are known, the vulnerability has received some community discussion and media coverage. Its FAUCET Risk Score is 61/100, indicating a moderate risk despite the lack of active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 16CPE matchmatch criteria | cpe:2.3:a:adobe:after_effects:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.